Impact
The WorkspaceManager._setup_session_persistence function in poco-agent's Claude File Handler contains a flaw that allows an attacker to manipulate the persistence setup so that the cleanup routine does not fully remove session data. Because the attack can be carried out remotely, an adversary could persist malicious state or leftovers, potentially exposing residual data or enabling repeated abuse of the session environment. The flaw is described as highly complex and difficult to exploit, yet public proof‑of‑concepts have already been released.
Affected Systems
poco-ai's poco-agent component, versions up to 0.5.4, is affected. Any deployment of poco-agent 0.5.4 or earlier that includes the Claude File Handler in its workspace management path is vulnerable.
Risk and Exploitability
The CVSS base score of 6.3 indicates a medium severity vulnerability. No EPSS score is available, and the issue is not listed in CISA KEV. The exploit was disclosed publicly and can be triggered remotely, but the required manipulation is sophisticated, making real‑world exploitation challenging. However, because the flaw results in incomplete cleanup, the risk remains significant if attackers achieve the initial manipulation step.
OpenCVE Enrichment